WordPress Plugin Vulnerabilities

Masteriyo LMS < 2.2.1 - Subscriber+ Privilege Escalation

Description

The plugin is vulnerable to Privilege Escalation due to an incorrect privilege assignment, making it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges.

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
daroo
Verified
Yes

Timeline

Publicly Published
2026-06-08 (about 2 months ago)
Added
2026-06-18 (about 2 months ago)
Last Updated
2026-08-21 (about 3 days ago)

Other